5. Encoding and Evolution
5.9 Production failure catalog for this chapter
| Symptom | Underlying mechanism |
|---|---|
| A field silently disappears after an edit | Unknown-field loss during a rolling upgrade (§0) |
| Large IDs are wrong by a few digits in the browser | 2⁵³ — JSON number parsed as an IEEE 754 double |
| RCE from a "harmless" data endpoint | Deserializing a language-native format from untrusted input |
| Decoding produces garbage after a schema change | Reused Protobuf tag number |
| Big values truncated after widening a type | Old code still holding a 32-bit variable |
| "Set to zero" indistinguishable from "not set" | proto3 default-value ambiguity |
| Every consumer breaks at once after a producer deploy | Added an Avro field without a default |
| Nothing can decode after a registry outage | Schema registry is on every consumer's critical path and unbacked-up |
| Old readers break after a field rename | Rename is backward but not forward compatible in Avro |
| gRPC traffic all lands on one backend | HTTP/2 multiplexing vs an L4 load balancer |
| Server burns CPU on abandoned requests | Deadline not propagated |
| Duplicate side effects after a retry | Timeout gave no information; no idempotence in the protocol |
| Deprecated API version can never be removed | No per-version usage instrumentation; no control over clients |
| Fields dropped as messages pass through a pipeline | Consumer republished after decoding into an old model |
Workflow throws NonDeterministicError after a deploy | Reordered or added activity calls, breaking replay |
| Payment charged twice | Third party not idempotent, no idempotency key |
| Clients see stale IPs after a failover | DNS caching used for a dynamic service population |
5.8 Technology deep dives
gRPC adds: HTTP/2 transport (multiplexed streams, header compression), four call types (unary, server-streaming, client-streaming, bidirectional), deadlines propagated through the…
5.10 Decision cheat sheet
Ask both directions separately. Can new code read old data? (backward) Can old code read new data? (forward) A change is only safe if the answer to both is yes for the duration of…